# Problem with mustache on watcher action

**URL:** <https://discuss.elastic.co/t/problem-with-mustache-on-watcher-action/184745>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [June 7, 2019, 11:10am UTC](https://discuss.elastic.co/t/problem-with-mustache-on-watcher-action/184745 "2019-06-07T11:10:28Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![franco.federico](https://avatars.discourse-cdn.com/v4/letter/f/67e7ee/32.png) [@franco.federico](https://discuss.elastic.co/u/franco.federico)\
**Post date:** [June 7, 2019, 11:10am UTC](https://discuss.elastic.co/t/problem-with-mustache-on-watcher-action/184745/1 "2019-06-07T11:10:28Z")

</div>

Hi all

I'm trying to do this action (a webhook)

```
"hook-tornado2": {
  "webhook": {
    "scheme": "http",
    "host": "localhost",
    "port": 8080,
    "method": "post",
    "path": "/event/failed-passwords",
    "params": {
      "token": "abc"
    },
    "headers": {},
    "body": {
      "source": "{{#toJson}}Watcher Notification Encountered {{ctx.payload.hits.total}} failed logon from user {{#ctx.payload.hits.hits.0}}{{_source.winlog.event_data.TargetUserName}}{{/ctx.payload.hits.hits.0}}.{{/toJson}}",
      "lang": "mustache"
    }
  }
}

```

I have this error

```
"actions": [
  {
    "id": "hook-tornado2",
    "type": "webhook",
    "status": "failure",
    "error": {
      "root_cause": [
        {
          "type": "general_script_exception",
          "reason": "Failed to compile inline script [{{#toJson}}Watcher Notification Encountered {{ctx.payload.hits.total}} failed logon from user {{#ctx.payload.hits.hits.0}}{{_source.winlog.event_data.TargetUserName}}{{/ctx.payload.hits.hits.0}}.{{/toJson}}] using lang [mustache]"
        }
      ],
      "type": "general_script_exception",
      "reason": "Failed to compile inline script [{{#toJson}}Watcher Notification Encountered {{ctx.payload.hits.total}} {{/toJson}}{{#toJson}}failed logon from user {{#ctx.payload.hits.hits.0}}{{_source.winlog.event_data.TargetUserName}}{{/ctx.payload.hits.hits.0}}.{{/toJson}}] using lang [mustache]",
      "caused_by": {
        "type": "mustache_exception",
        "reason": "Mustache function [toJson] must contain one and only one identifier"
      }
    }
  },

```

I need to compose the message, in output of the body like an email action.

Is it possible?

Thank you  
Franco

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [June 7, 2019, 12:05pm UTC](https://discuss.elastic.co/t/problem-with-mustache-on-watcher-action/184745/2 "2019-06-07T12:05:59Z")

</div>

what are you trying to achieve by using `toJson` here? That function is able to convert a map to valid JSON, but you have been putting sentences in there - so I am not sure what your expected final result is.

Please show an example of the expected output. Thanks!

---

<div class="post-metadata">

**Author:** ![franco.federico](https://avatars.discourse-cdn.com/v4/letter/f/67e7ee/32.png) [@franco.federico](https://discuss.elastic.co/u/franco.federico)\
**Post date:** [June 7, 2019, 1:13pm UTC](https://discuss.elastic.co/t/problem-with-mustache-on-watcher-action/184745/3 "2019-06-07T13:13:41Z")

</div>

I'd like to do a JSON like I did with

> "body": "{{#toJson}}ctx.payload{{/toJson}}"

but I want to create a JSON like this

```
{
    "message": "TEXT"
}    

```

with the parameter of ctx.pyaload

Thank you  
Franco

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [June 7, 2019, 2:07pm UTC](https://discuss.elastic.co/t/problem-with-mustache-on-watcher-action/184745/4 "2019-06-07T14:07:41Z")

</div>

what you would need to do is running a transform that returns a map `return ['message': 'TEXT']`, then you can do `{{#toJson}}ctx.payload{{/toJson}}`

--Alex

---

<div class="post-metadata">

**Author:** ![franco.federico](https://avatars.discourse-cdn.com/v4/letter/f/67e7ee/32.png) [@franco.federico](https://discuss.elastic.co/u/franco.federico)\
**Post date:** [June 7, 2019, 4:23pm UTC](https://discuss.elastic.co/t/problem-with-mustache-on-watcher-action/184745/5 "2019-06-07T16:23:57Z")

</div>

Hi

thank you for response. Could you give me an example of transformation on action. I tried to do this, but I not sure to have understand

```auto
    "hook-tornado2": {
      "webhook": {
        "transform" : {
            "script" : "return ['msg' : 'Watcher Notification Encountered {{ctx.payload.hits.total}} failed logon from user {{#ctx.payload.hits.hits.0}}{{_source.winlog.event_data.TargetUserName}}{{/ctx.payload.hits.hits.0}}.']" 
        },          
        "scheme": "http",
        "host": "localhost",
        "port": 8080,
        "method": "post",
        "path": "/event/failed-passwords",
        "params": {
          "token": "abc"
        },
        "headers": {},
        "body": "{{#toJson}}ctx.payload{{/toJson}}"
      }
    }

```

With this I have the parameter ctx.payload.msg, is it true?

Thank you  
Franco

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [June 10, 2019, 1:11pm UTC](https://discuss.elastic.co/t/problem-with-mustache-on-watcher-action/184745/6 "2019-06-10T13:11:30Z")

</div>

The JSON output of this will be

```auto
{
  "msg": "Watcher Notification..."
}

```

---

<div class="post-metadata">

**Author:** ![franco.federico](https://avatars.discourse-cdn.com/v4/letter/f/67e7ee/32.png) [@franco.federico](https://discuss.elastic.co/u/franco.federico)\
**Post date:** [June 10, 2019, 3:27pm UTC](https://discuss.elastic.co/t/problem-with-mustache-on-watcher-action/184745/7 "2019-06-10T15:27:58Z")

</div>

Hi @spinscale I have just simulate this webhook and I have a message of error

**`Preformatted text`[parse\_exception] could not parse http request template. unexpected object field [transform]**

Why?

Thank you  
Franco

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [June 10, 2019, 3:46pm UTC](https://discuss.elastic.co/t/problem-with-mustache-on-watcher-action/184745/8 "2019-06-10T15:46:06Z")

</div>

please provide the full watch and the output of the execute watch API. Thanks.

---

<div class="post-metadata">

**Author:** ![franco.federico](https://avatars.discourse-cdn.com/v4/letter/f/67e7ee/32.png) [@franco.federico](https://discuss.elastic.co/u/franco.federico)\
**Post date:** [June 10, 2019, 3:51pm UTC](https://discuss.elastic.co/t/problem-with-mustache-on-watcher-action/184745/9 "2019-06-10T15:51:40Z")

</div>

Hi

the code of watcher is

```
{
  "trigger": {
    "schedule": {
      "interval": "5m"
    }
  },
  "input": {
    "search": {
      "request": {
        "search_type": "query_then_fetch",
        "indices": [
          "winlogbeat-*"
        ],
        "types": [],
        "body": {
          "query": {
            "bool": {
              "filter": [
                {
                  "range": {
                    "@timestamp": {
                      "from": "now-5m",
                      "to": "now"
                    }
                  }
                },
                {
                  "match": {
                    "winlog.event_id": "4625"
                  }
                }
              ]
            }
          },
          "aggs": {
            "users": {
              "terms": {
                "field": "winlog.event_data.TargetUserName.keyword",
                "size": 10
              }
            }
          }
        }
      }
    }
  },
  "condition": {
    "compare": {
      "ctx.payload.hits.total": {
        "gte": 10
      }
    }
  },
  "actions": {
    "my-logging-action": {
      "logging": {
        "level": "info",
        "text": "Watcher Notification Encountered {{ctx.payload.hits.total}} failed logon from user {{#ctx.payload.hits.hits.0}}{{_source.winlog.event_data.TargetUserName}}{{/ctx.payload.hits.hits.0}}."
      }
    },
    "hook-tornado": {
      "webhook": {
        "scheme": "http",
        "host": "localhost",
        "port": 8080,
        "method": "post",
        "path": "/event/webhook-elastic",
        "params": {
          "token": "123"
        },
        "headers": {},
        "body": "{{#toJson}}ctx.payload{{/toJson}}"
      }
    },
    "hook-tornado2": {
      "webhook": {
        "transform" : {
            "script" : "return ['msg' : 'Watcher Notification Encountered {{ctx.payload.hits.total}} failed logon from user {{#ctx.payload.hits.hits.0}}{{_source.winlog.event_data.TargetUserName}}{{/ctx.payload.hits.hits.0}}.']" 
        },               
        "scheme": "http",
        "host": "localhost",
        "port": 8080,
        "method": "post",
        "path": "/event/failed-passwords",
        "params": {
          "token": "abc"
        },
        "headers": {},
        "body": "{{#toJson}}ctx.payload{{/toJson}}"
      }
    }
  }
}

```

I simulate before to save the watcher. I have this error

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/c/a/cab0081050c078b5d1dd47008f38cafa86037f4b.png)

Thank you  
Franco

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [June 10, 2019, 4:07pm UTC](https://discuss.elastic.co/t/problem-with-mustache-on-watcher-action/184745/10 "2019-06-10T16:07:29Z")

</div>

the `transform` needs to be placed outside of the `webhook` but inside of the `hook-tornado` field as a sibling to `webhook`

---

<div class="post-metadata">

**Author:** ![franco.federico](https://avatars.discourse-cdn.com/v4/letter/f/67e7ee/32.png) [@franco.federico](https://discuss.elastic.co/u/franco.federico)\
**Post date:** [June 10, 2019, 4:24pm UTC](https://discuss.elastic.co/t/problem-with-mustache-on-watcher-action/184745/11 "2019-06-10T16:24:11Z")

</div>

So I changed the watcher.

Now I have

```
{
  "trigger": {
    "schedule": {
      "interval": "5m"
    }
  },
  "input": {
    "search": {
      "request": {
        "search_type": "query_then_fetch",
        "indices": [
          "winlogbeat-*"
        ],
        "types": [],
        "body": {
          "query": {
            "bool": {
              "filter": [
                {
                  "range": {
                    "@timestamp": {
                      "from": "now-5m",
                      "to": "now"
                    }
                  }
                },
                {
                  "match": {
                    "winlog.event_id": "4625"
                  }
                }
              ]
            }
          },
          "aggs": {
            "users": {
              "terms": {
                "field": "winlog.event_data.TargetUserName.keyword",
                "size": 10
              }
            }
          }
        }
      }
    }
  },
  "condition": {
    "compare": {
      "ctx.payload.hits.total": {
        "gte": 10
      }
    }
  },
  "transform" : {
    "script" : "return ['msg' : 'Watcher Notification Encountered {{ctx.payload.hits.total}} failed logon from user {{#ctx.payload.hits.hits.0}}{{_source.winlog.event_data.TargetUserName}}{{/ctx.payload.hits.hits.0}}.']" 
  },   
  "actions": {
    "my-logging-action": {
      "logging": {
        "level": "info",
        "text": "Watcher Notification Encountered {{ctx.payload.hits.total}} failed logon from user {{#ctx.payload.hits.hits.0}}{{_source.winlog.event_data.TargetUserName}}{{/ctx.payload.hits.hits.0}}."
      }
    },
    "hook-tornado": {
      "webhook": {
        "scheme": "http",
        "host": "localhost",
        "port": 8080,
        "method": "post",
        "path": "/event/webhook-elastic",
        "params": {
          "token": "123"
        },
        "headers": {},
        "body": "{{#toJson}}ctx.payload{{/toJson}}"
      }
    },
    "hook-tornado2": {
      "webhook": {
        "scheme": "http",
        "host": "localhost",
        "port": 8080,
        "method": "post",
        "path": "/event/failed-passwords",
        "params": {
          "token": "abc"
        },
        "headers": {},
        "body": "{{#toJson}}ctx.payload{{/toJson}}"
      }
    }
  }
}

```

The simulation is ok.

At the moment I don't see the log message of the action because I think I change the ctx, is it correct?

I found in the pyalod only the message that I use in transform instead of **ctx.payload**

Could I pass all context and adding to it the msg?

Thank you  
Franco

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [June 11, 2019, 7:11am UTC](https://discuss.elastic.co/t/problem-with-mustache-on-watcher-action/184745/12 "2019-06-11T07:11:19Z")

</div>

the `transform` you specified is done after the condition - which means that the logging action will not log anything. You can have a transform in your action as well, I think that should be the way to go here.

In order to include the original payload you could do something like this

```auto
def payload = ctx.payload;
payload.msg = 'foo'
return payload;

```

---

<div class="post-metadata">

**Author:** ![franco.federico](https://avatars.discourse-cdn.com/v4/letter/f/67e7ee/32.png) [@franco.federico](https://discuss.elastic.co/u/franco.federico)\
**Post date:** [June 11, 2019, 9:18pm UTC](https://discuss.elastic.co/t/problem-with-mustache-on-watcher-action/184745/13 "2019-06-11T21:18:12Z")

</div>

I tried with your suggestion but in the simulated I don't see the correct result in the msg

I attach my webhook configuration

```
"hook-tornado2": {
  "transform" : { 
  	"script" : "def payload = ctx.payload; payload.msg = 'Watcher Notification Encountered {{#payload.hits.total}} failed logon from user {{#payload.hits.hits.0}}{{_source.winlog.event_data.TargetUserName}}{{/.payload.hits.hits.0}}.'; return payload;"
  },        
  "webhook": {
    "scheme": "http",
    "host": "localhost",
    "port": 8080,
    "method": "post",
    "path": "/event/failed-passwords",
    "params": {
      "token": "abc"
    },
    "headers": {},
    "body": "{{#toJson}}ctx.payload{{/toJson}}"

```

And in the simulated I had

`"msg": "Watcher Notification Encountered {{#payload.hits.total}} failed logon from user {{#payload.hits.hits.0}}{{_source.winlog.event_data.TargetUserName}}{{/.payload.hits.hits.0}}.",`

How could I recall the value in payload?

Thank you  
Franco

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [June 12, 2019, 12:33pm UTC](https://discuss.elastic.co/t/problem-with-mustache-on-watcher-action/184745/14 "2019-06-12T12:33:30Z")

</div>

you need to use `{{ctx.payload...`

---

<div class="post-metadata">

**Author:** ![franco.federico](https://avatars.discourse-cdn.com/v4/letter/f/67e7ee/32.png) [@franco.federico](https://discuss.elastic.co/u/franco.federico)\
**Post date:** [June 12, 2019, 1:07pm UTC](https://discuss.elastic.co/t/problem-with-mustache-on-watcher-action/184745/15 "2019-06-12T13:07:28Z")

</div>

Hi @spinscale I use the ctx.payload but I have the same

`"msg": "Watcher Notification Encountered {{#ctx.payload.hits.total}} failed logon from user {{#ctx.payload.hits.hits.0}}{{_source.winlog.event_data.TargetUserName}}{{/ctx.payload.hits.hits.0}}.",`

Is it possible that in this msg the script doesn't see other parameter and/or variable?

Thyank you  
Franco

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [June 12, 2019, 1:30pm UTC](https://discuss.elastic.co/t/problem-with-mustache-on-watcher-action/184745/16 "2019-06-12T13:30:41Z")

</div>

You are only referring to the first element of the hits, instead of looping through all of them. You either need to use `{{#ctx.payload.hits.hits}}` or if you just want to access the first value you can go with `{{ctx.payload.hits.hits.0._source.winlog.event_data.TargetUserName}}`

---

<div class="post-metadata">

**Author:** ![franco.federico](https://avatars.discourse-cdn.com/v4/letter/f/67e7ee/32.png) [@franco.federico](https://discuss.elastic.co/u/franco.federico)\
**Post date:** [June 13, 2019, 12:05pm UTC](https://discuss.elastic.co/t/problem-with-mustache-on-watcher-action/184745/17 "2019-06-13T12:05:03Z")

</div>

Hello @spinscale

I changed webhook

```
"hook-tornado2": {
  "transform" : { 
  	"script" : "def payload = ctx.payload; payload.msg = 'Watcher Notification Encountered {{payload.hits.totals}} failed logon from user {{payload.hits.hits.0._source.winlog.event_data.TargetUserName}}.'; return payload;"
  },           
  "webhook": {
    "scheme": "http",
    "host": "localhost",
    "port": 8080,
    "method": "post",
    "path": "/event/failed-passwords",
    "params": {
      "token": "abc"
    },
    "headers": {},
    "body": "{{#toJson}}payload{{/toJson}}"
  }
} 

```

But the result is similar to the other results

`"msg": "Watcher Notification Encountered {{payload.hits.totals}} failed logon from user {{payload.hits.hits.0._source.winlog.event_data.TargetUserName}}.",`

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [June 13, 2019, 2:39pm UTC](https://discuss.elastic.co/t/problem-with-mustache-on-watcher-action/184745/18 "2019-06-13T14:39:20Z")

</div>

please always share the **whole** watch plus the complete output of the execute watch API again in order to debug better. Note, the `body` needs to specify `ctx.payload`

---

<div class="post-metadata">

**Author:** ![franco.federico](https://avatars.discourse-cdn.com/v4/letter/f/67e7ee/32.png) [@franco.federico](https://discuss.elastic.co/u/franco.federico)\
**Post date:** [June 13, 2019, 2:53pm UTC](https://discuss.elastic.co/t/problem-with-mustache-on-watcher-action/184745/19 "2019-06-13T14:53:27Z")

</div>

The complete watch is the following

```
{
  "trigger": {
    "schedule": {
      "interval": "5m"
    }
  },
  "input": {
    "search": {
      "request": {
        "search_type": "query_then_fetch",
        "indices": [
          "winlogbeat-*"
        ],
        "types": [],
        "body": {
          "query": {
            "bool": {
              "filter": [
                {
                  "range": {
                    "@timestamp": {
                      "from": "now-5m",
                      "to": "now"
                    }
                  }
                },
                {
                  "match": {
                    "winlog.event_id": "4625"
                  }
                }
              ]
            }
          },
          "aggs": {
            "users": {
              "terms": {
                "field": "winlog.event_data.TargetUserName.keyword",
                "size": 10
              }
            }
          }
        }
      }
    }
  },
  "condition": {
    "compare": {
      "ctx.payload.hits.total": {
        "gte": 10
      }
    }
  },
  "actions": {
    "my-logging-action": {
      "logging": {
        "level": "info",
        "text": "Watcher Notification Encountered {{ctx.payload.hits.total}} failed logon from user {{#ctx.payload.hits.hits.0}}{{_source.winlog.event_data.TargetUserName}}{{/ctx.payload.hits.hits.0}}."
      }
    },
    "hook-tornado": {
      "webhook": {
        "scheme": "http",
        "host": "localhost",
        "port": 8080,
        "method": "post",
        "path": "/event/webhook-elastic",
        "params": {
          "token": "123"
        },
        "headers": {},
        "body": "{{#toJson}}ctx.payload{{/toJson}}"
      }
    },
    "hook-tornado2": {
      "transform" : { 
      	"script" : "def payload = ctx.payload; payload.msg = 'Watcher Notification Encountered {{payload.hits.totals}} failed logon from user {{payload.hits.hits.0._source.winlog.event_data.TargetUserName}}.'; return payload;"
      },           
      "webhook": {
        "scheme": "http",
        "host": "localhost",
        "port": 8080,
        "method": "post",
        "path": "/event/failed-passwords",
        "params": {
          "token": "abc"
        },
        "headers": {},
        "body": "{{#toJson}}payload{{/toJson}}"
      }
    }
  }
}

```

The simulate watch is the following

![image](https://us1.discourse-cdn.com/elastic/original/3X/2/2/22a907056d8162d20d724a2caa5ab2eb949dce5e.png)

and I insert the output to this json blob  
[https://jsonblob.com/d3b15a81-8dea-11e9-b697-7bc43a3afcc5](https://jsonblob.com/d3b15a81-8dea-11e9-b697-7bc43a3afcc5).

Thank you  
Franco

---

<div class="post-metadata">

**Author:** ![franco.federico](https://avatars.discourse-cdn.com/v4/letter/f/67e7ee/32.png) [@franco.federico](https://discuss.elastic.co/u/franco.federico)\
**Post date:** [June 14, 2019, 8:07am UTC](https://discuss.elastic.co/t/problem-with-mustache-on-watcher-action/184745/20 "2019-06-14T08:07:22Z")

</div>

Hi @spinscale do you see my last response?

Do you have an idea how could I solve this problem.

Thank you  
Franco

[Next page](https://discuss.elastic.co/t/problem-with-mustache-on-watcher-action/184745.md?page=2)
